← Back to Perkaway

PRIVACY

Your privacy, in plain language.

About Perkaway

Perkaway helps you compare cards, record rewards manually, and save plans. Flight and hotel search is available only when enabled, and search requests are shared with the travel service providing results. No tickets are booked, no points are transferred, and bank and rewards accounts are not connected automatically.

Restaurant search and maps

When enabled, restaurant searches and requested map views use Google Maps Platform. Google receives your search terms; choosing “Near me” also sends your location after you grant browser permission. You can type a city instead. We do not save your precise dining-search location to your profile. Restaurant details and photos are requested when you open them, not copied into a permanent restaurant database.

Google Maps features are subject to the Google Maps terms and Google privacy policy. Card-program information is maintained separately and is not verified by Google. Reservation links take you to the provider, where its terms and privacy policy apply.

Previously connected a test account?

Automatic tracking is coming soon. If you previously tested a Plaid connection, the following explains how its data is handled. Use “Report a problem” to request an export or removal of that test data.

Earlier tests used Plaid’s test environment with separate consent, not real bank credentials. Test records include consent version/time, account labels and masked endings, connection status, and encrypted connection tokens on the server. For the one USD credit-card account you select, we store transaction identifiers, dates, signed amounts, pending status and a synchronization cursor, up to 500 transactions. We initially request 30 days of activity, but returned coverage may be incomplete.

This activity does not establish loyalty balances or bonus eligibility and does not change your manual points or earning plan. Tokens and cursors are not sent to the browser or included in your account data download. The account data download excludes bank-connection records. Use the separate bank-data export, when available, for your stored test activity, account labels, consent and connection status. Downloaded copies remain on your device after disconnect. Ask the project operator for deletion.

Disconnect requests clear current stored activity and ask Plaid to remove access. If cleanup cannot be confirmed, encrypted credentials and connection metadata may remain until the operator resolves it. Retained backups may still contain earlier records; disconnect is not an immediate purge of backups. Contact the operator to request complete account deletion and confirm retention handling before testing.

What we store

Your email and authentication information are managed by Amazon Cognito. Your display name, starting goal, airport preference, points experience, manually entered rewards program names/categories, balances and units, dates checked and reported expirations, card nicknames and currencies, annual fees, saved card shortlists, monthly budgets, manually entered asset and liability balances, manual or CSV-imported transactions (date, description, amount, type, category and account label), trip-fund amounts, bonus terms/progress, earning targets, current and saved trips, and checklist/lesson progress are stored in AWS. We record that you accepted this notice. Don’t enter card numbers, loyalty account numbers, bank passwords, or other sensitive identifiers.

Who can access it

You must be signed in to access your saved information. The project operator and authorized AWS administrators can access stored records to run and troubleshoot the beta. This is not end-to-end encrypted storage.

Browser storage and external services

Card-finder spending answers and the cards you select as owned remain in the current page’s memory; they are not saved to your account. Choosing Save shortlist passes only catalog card identifiers to the account page URL. You review that selection before saving it. Issuer links take you to an external site; we do not submit card applications.

We use browser storage to keep you signed in. Your profile and wallet are saved to your account. Fonts are requested from Google Fonts and destination imagery from Unsplash. Card artwork is requested directly from issuer-hosted image services without sending a referrer; these services receive ordinary connection information such as your IP address. There are no advertising trackers or payment integrations in this beta.

Control and retention

You can edit your profile, balances and earning plan, and download your account data from Privacy & data. You can also request account deletion there. Beta data remains until deleted by the operator; access may end and data may be reset when this test closes. Please export anything you want to keep.

Help and support

Problem reports include the section name and the text you choose to send. Crash reports contain only a random reference and section name, not error text, transaction data or authentication tokens. The operator can review these reports. Support records are scheduled for removal after 30 days once hosting retention is configured; backup copies follow the operator’s retention process. A deletion request is not a completed deletion.

Use your account safely

Use a unique password. Example balances are fine if you prefer not to enter real ones. Confirm reward availability and terms with the program before redeeming or transferring points.